Can you please help me figure out why I am getting the following error message for network login failure where the login shows a disabled guest account? First some background, I am running a Dell d830 with Vista ultimate and have all passwords for web on smartcard, encrypt all slightly personal data on the computer using ntfs and have all extremely important data is kept on external hard drive. I am logging in under regular user acct (using a fingerprint scanner in conjunction with my smartcard to validate both bios and windows login). For internet access I am using a wireless router with firewall and am not broadcasting sid, using wep-psk with tkip, and use mac filtering for the two laptops that connect in my household. I am running a firewall, spamblocker, virus checker on the computers also, I have renamed the guest account and disabled it and turned off anonymous access and denied network access to both the guest and anonymous users, denied local access to the guest account, and do not use sharing and disabled all administrative shares. I have run the Microsoft baseline analyzer and is gives me a clean bill?all updates applied and unnecessary services turned off. Can anyone tell my why yesterday I got the audit failure for the guest account? I have had the computer up only since 7-1-08.
Here is the message:
Audit Failure 8/5/2008 10:08:04 AM Microsoft Windows security auditing. 4625 Logon
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 8/5/2008 10:08:04 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: (name of my computer)
Description:
An account failed to log on.
Subject:
Security ID: (PC-name)\(my login acct name)
Account Name: (my login acct)
Account Domain: (pc-name)
Logon ID: 0x73489
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: (guest acct name)
Account Domain: (pc name)
Failure Information:
Failure Reason: Account currently disabled.
Status: 0xc000006e
Sub Status: 0xc0000072
Process Information:
Caller Process ID: 0xe44
Caller Process Name: C:\Windows\explorer.exe
Network Information:
Workstation Name: (pc name)
Source Network Address: –
Source Port: –
Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: –
Package Name (NTLM only): –
Key Length: 0